首页> 外国专利> Detection of malicious web activity in enterprise computer networks

Detection of malicious web activity in enterprise computer networks

机译:检测企业计算机网络中的恶意Web活动

摘要

A processing device in one embodiment comprises a processor coupled to a memory and is configured to obtain internal log data of a computer network of an enterprise, to extract values of a plurality of designated internal features from the log data, to obtain additional data from one or more external data sources, and to extract values of a plurality of designated external features from the additional data. The extracted values are applied to a regression model based on the internal and external features to generate malicious activity risk scores for respective ones of a plurality of domains, illustratively external domains having fully-qualified domain names (FQDNs). A subset of the domains are identified based on their respective malicious activity risk scores, and one or more proactive security measures are taken against the identified subset of domains. The processing device may be implemented in the computer network or an associated network security system.
机译:一个实施例中的处理设备包括耦合到存储器的处理器,并且被配置为获取企业的计算机网络的内部日志数据,从日志数据中提取多个指定的内部特征的值,从一个数据库获取附加数据。一个或多个外部数据源,并从附加数据中提取多个指定外部特征的值。所提取的值基于内部和外部特征被应用于回归模型,以针对多个域中的各个域生成恶意活动风险评分,这些域例如是具有完全限定域名(FQDN)的外部域。根据域的子集各自的恶意活动风险评分来识别域的子集,并对识别出的域子集采取一种或多种主动安全措施。该处理设备可以在计算机网络或相关联的网络安全系统中实现。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号